← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
May 14, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
1Zohocorp
3Manageengine Servicedesk Plus
Manageengine Servicedesk Plus MspManageengine Supportcentre Plus
Jun 17, 2026
Mar 21, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Mar 3, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
1Zohocorp
1Manageengine Endpoint Central
Jun 17, 2026
Feb 5, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
1Zohocorp
1Manageengine Analytics Plus
Jun 17, 2026
Nov 27, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Nov 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
1Zohocorp
1Manageengine Sharepoint Manager Plus
Jun 17, 2026
Nov 8, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Nov 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
1Zohocorp
1Manageengine Endpoint Central
Jun 17, 2026
Nov 7, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Nov 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Nov 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Nov 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Oct 24, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
1Zohocorp
1Manageengine Endpoint Central
Jun 17, 2026
Aug 30, 2024
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Aug 30, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
1Zohocorp
2Manageengine Pam360
Manageengine Password Manager Pro
Jun 17, 2026
Aug 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
1Zohocorp
3Manageengine Servicedesk Plus
Manageengine Servicedesk Plus MspManageengine Supportcenter Plus
Jun 17, 2026
Aug 23, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; Serv...Show more
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.Show less
1Zohocorp
3Manageengine Servicedesk Plus
Manageengine Servicedesk Plus MspManageengine Supportcenter Plus
Jun 17, 2026
Aug 23, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Aug 23, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.